Show filters
64 Total Results
Displaying 21-30 of 64
Sort by:
Attacker Value
Unknown

CVE-2012-6645

Disclosure Date: April 08, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the autocomplete functionality in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via the title of a node, a different vulnerability than CVE-2012-1561.
0
Attacker Value
Unknown

CVE-2012-1561

Disclosure Date: April 08, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "checkbox and radio button functionalities."
0
Attacker Value
Unknown

CVE-2012-6065

Disclosure Date: December 03, 2012 (last updated October 05, 2023)
The OM Maximenu module 6.x-1.43 and earlier for Drupal, when the "Title has PHP" option is enabled, allows remote authenticated users with the "Administer OM Maximenu" permission to execute arbitrary PHP code via a "Link Title," a different vulnerability than CVE-2012-5553.
0
Attacker Value
Unknown

CVE-2012-5553

Disclosure Date: December 03, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the OM Maximenu module 6.x-1.x before 6.x-1.44 and 7.x-1.x before 7.x-1.44 for Drupal allow remote authenticated users with the "administer OM Maximenu" permission to inject arbitrary web script or HTML via the (1) Menu Title (2) Link Title, (3) Path Query, (4) Anchor, or (5) vocabulary names.
0
Attacker Value
Unknown

CVE-2012-1649

Disclosure Date: September 09, 2012 (last updated October 05, 2023)
Cool Aid module before 6.x-1.9 for Drupal does not enforce access restrictions, which allows remote authenticated users with the administer coolaid permission to modify arbitrary pages via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-1648

Disclosure Date: September 09, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Cool Aid module before 6.x-1.9 for Drupal allows remote authenticated users with the administer coolaid permission to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-1641

Disclosure Date: August 28, 2012 (last updated October 05, 2023)
The finder_import function in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote authenticated users with the administer finder permission to execute arbitrary PHP code via admin/build/finder/import.
0
Attacker Value
Unknown

CVE-2010-4864

Disclosure Date: October 05, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cm_id parameter in an equip presenta action to index.php.
0
Attacker Value
Unknown

CVE-2010-2857

Disclosure Date: July 25, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the cid parameter to album.html.
0
Attacker Value
Unknown

CVE-2010-2350

Disclosure Date: June 21, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in the PNG decoder in Ziproxy 3.1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNG file.
0